Financial crime compliance is one of the largest enterprise software categories in the world. Banks spend over €200 billion per year on it. The tools they use are, by technology standards, ancient. Batch-processing rule engines designed in the 2000s, generating 95% false positive rates, running on architectures that predate cloud computing.

In any other market, this gap between spending and technology quality would have attracted disruptors years ago. In compliance, it hasn't. Understanding why tells you a lot about what needs to change for disruption to actually happen.

The Three Locks

There are three interlocking reasons compliance technology has resisted disruption.

The first is buyer psychology. Compliance officers don't buy technology the way a CTO or a VP of Engineering does. They buy based on risk. The question isn't "is this better?" The question is "if this goes wrong, what happens to me personally?" When the downside of a bad technology choice includes personal criminal liability (regulators investigated individual board members at both ING and ABN AMRO), the rational response is to buy what everyone else is buying. The incumbent vendor may be mediocre, but mediocre and widely adopted is safer than excellent and unproven.

The second is regulatory validation. Banks can't deploy a new monitoring system without their regulator being comfortable with it. This doesn't mean formal approval. Most regulators don't certify compliance software. But there's an informal validation process: the bank tells the regulator what system they're using, the regulator asks questions about it, and if the regulator has never heard of the vendor, the questions get harder and the scrutiny intensifies. This creates a chicken-and-egg problem. New vendors can't get regulatory familiarity without bank deployments, and banks won't deploy without regulatory familiarity.

The third is integration depth. Enterprise AML systems are deeply integrated into a bank's infrastructure. They connect to core banking systems, payment processors, customer databases, case management platforms, and regulatory reporting tools. Replacing them is a multi-year project that touches dozens of other systems. Even if a bank wants to switch, the migration cost and risk are enormous.

Together, these three locks create a market where incumbents survive not because they're good, but because the barriers to replacing them are so high that buyers don't bother trying.

What's Breaking the Locks

Each of these locks is weakening simultaneously. That hasn't happened before.

Buyer psychology is shifting because the cost of staying with incumbent systems is becoming visible at the board level. When ING pays €775 million and ABN AMRO pays €480 million in fines, the "safe choice" isn't safe anymore. When 95% false positive rates mean thousands of analysts doing unproductive work, the CFO starts asking questions the CCO used to deflect. The status quo has always had hidden costs, but those costs are now large enough to be line items in board presentations.

Regulatory validation is being addressed through sandbox programmes. The FCA's regulatory sandbox and DNB's InnovationHub exist specifically to break the chicken-and-egg problem. A startup that enters the sandbox and gets a positive assessment from the regulator has solved the validation problem without needing existing bank deployments. This is a recent institutional innovation, and it fundamentally changes the go-to-market dynamics for compliance technology startups.

Integration depth is being reduced by modern API architectures. Ten years ago, replacing a monitoring system meant ripping out and replacing deep mainframe integrations. Today, most banks have middleware layers, API gateways, and data lakes that decouple the monitoring system from the core infrastructure. A new monitoring engine that ingests data via standard APIs and exports alerts via standard formats can be deployed alongside (not instead of) the existing system. This enables a phased migration rather than a big-bang replacement, which dramatically reduces deployment risk.

The AMLR Catalyst

Even with the locks weakening, inertia might still hold. Banks might continue extending contracts with incumbent vendors, upgrading incrementally, and hoping for the best. This is what has happened in every previous regulatory cycle.

AMLR changes the equation because it makes incremental upgrades insufficient. The regulation doesn't just raise the bar. It changes what the bar is made of. Batch processing won't satisfy real-time monitoring expectations. Centralised data pooling won't satisfy privacy-preserving detection requirements. Opaque AI won't satisfy explainability standards.

For the first time, banks can't comply by tuning their existing systems. They need different systems. And they need them by mid-2027.

This creates the forcing function that has been absent in every previous disruption attempt. The demand is mandatory. The timeline is fixed. The existing solutions are architecturally inadequate. And the sandbox programmes provide a path for new entrants to establish regulatory credibility.

Why Previous Challengers Didn't Break Through

It's worth understanding why Sardine ($145M raised), Hawk AI ($83M raised), and other funded challengers haven't disrupted the Tier-1 bank market despite strong funding and good technology.

The answer isn't that their products are bad. They're genuinely better than legacy systems in many dimensions. The answer is that they're architecturally similar to the incumbents. They run on CPU infrastructure, process in cloud environments, and use conventional machine learning for alert scoring. They're better versions of the existing architecture.

Better-but-similar is enough to win fintech customers and mid-market banks that don't have deep incumbent lock-in. It's not enough to displace NICE Actimize or Oracle at a Tier-1 bank. The improvement isn't large enough to justify the migration risk, and the architecture doesn't offer capabilities that the incumbent fundamentally can't match.

Disruption in this market requires an architectural step change, not an incremental improvement. GPU-native processing, privacy-preserving cross-institutional detection, and cryptographic regulatory verification are capabilities that existing architectures can't absorb. They require a rebuild from first principles. That's the difference between a challenger and a disruptor.

The Window

The investment window for compliance technology disruption is defined by two events. The opening event is the finalisation of AMLR and the EU AI Act technical standards, which has happened. Banks know what they need to comply with, and they're beginning to evaluate alternatives. The closing event is the procurement commitment wave, when the majority of banks have selected their AMLR-compliant monitoring solution and signed contracts.

Based on typical enterprise procurement timelines, the commitment wave will run through 2026 into early 2027. Banks will be evaluating in 2026 and deploying in 2027. Companies that are positioned as credible alternatives during the evaluation phase will be in the running. Companies that aren't visible by then will miss the cycle.

This window is narrow by enterprise standards. It's also unusually predictable, because the regulatory deadline is fixed and applies uniformly across the EU. For investors, predictable timing in a mandatory-spend market with weak incumbents is about as good as the setup gets.